PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 982,27 KB
SHA-256 Hash: 2AEE6C5DE5D0F0875D7CD4D9E990D22EEDAD32AC88EADCAB0EEA3D1F49D02F1A
SHA-1 Hash: 18447FCE2369CA4B125ED95393F6A3A3B799B913
MD5 Hash: 54D32E84641970E6B1141339F915B497
Imphash: 3D95ADBF13BBE79DC24DCCB401C12091
MajorOSVersion: 5
MinorOSVersion: 1
CheckSum: 000FF202
EntryPoint (rva): 29AB7
SizeOfHeaders: 400
SizeOfImage: FC000
ImageBase: 400000
Architecture: x86
ImportTable: B9004
IAT: 8F000
Characteristics: 122
TimeDateStamp: 675C675B
Date: 13/12/2024 16:56:59
File Type: EXE
Number Of Sections: 5
ASLR: Enabled
Section Names: .text, .rdata, .data, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows GUI
UAC Execution Level Manifest: requireAdministrator

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 8DA00 1000 8D9DD
6.6706
3092303.03
.rdata
0x40000040
Initialized Data
Readable
8DE00 2CE00 8F000 2CC42
5.7683
4684319.68
.data
0xC0000040
Initialized Data
Readable
Writeable
BAC00 6200 BC000 9D54
1.9825
4291322.57
.rsrc
0x40000040
Initialized Data
Readable
C0E00 2A400 C6000 2A2ED
7.8967
71316.18
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
EB200 A600 F1000 A57A
5.2773
1489786.25
Description
OriginalFilename: Macro.exe
CompanyName: Logitech
LegalCopyright: Logitech
ProductName: 1.0.0
FileVersion: 0.1.0.0
FileDescription: Logitech
ProductVersion: 1.1.0.0
Language: English (United Kingdom) (ID=0x809)
CodePage: Unicode (UTF-16 LE) (0x4B0)

Entry Point
The section number (1) - (.text) have the Entry Point
Information -> EntryPoint (calculated) - 28EB7
Code -> E877CE0000E97FFEFFFFCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC57568B7424108B4C24148B7C240C8BC18BD103C63BFE76083B
Assembler
|CALL 0X436933
|JMP 0X429940
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|PUSH EDI
|PUSH ESI
|MOV ESI, DWORD PTR [ESP + 0X10]
|MOV ECX, DWORD PTR [ESP + 0X14]
|MOV EDI, DWORD PTR [ESP + 0XC]
|MOV EAX, ECX
|MOV EDX, ECX
|ADD EAX, ESI
|CMP EDI, ESI
|JBE 0X429AF0
Signatures
Rich Signature Analyzer:
Code -> FD64C89EB905A6CDB905A6CDB905A6CD27A561CDB805A6CD48C36BCD8A05A6CD48C368CD1705A6CD48C369CD8B05A6CDB07D25CDB005A6CDB07D35CD9C05A6CDB905A7CDAD07A6CDDFEB7ECDF405A6CDDFEB6BCDBB05A6CDDFEB6FCDB805A6CDB90531CDB805A6CDDFEB6ACDB805A6CD52696368B905A6CD
Footprint md5 Hash -> FB7356D50041EAE0004BFF8AD52855C5
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Compiler: Microsoft Visual C ++
Compiler: Microsoft Visual C ++ 6 DLL
Compiler: Autoit 3 - (You can use a decompiler for this...)
Detect It Easy (die)
PE: compiler: Microsoft Visual C/C++(2012)[-]
PE: linker: Microsoft Linker(11.0)[-]
Entropy: 6.89805

Suspicious Functions
Library Function Description
KERNEL32.DLL VirtualAlloc Reserve, commit, or both, a region of memory within the virtual address space of a process.
KERNEL32.DLL CopyFileW Copies an existing file to a new file.
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL LoadLibraryA Loads the specified module into the address space of the calling process.
KERNEL32.DLL LoadLibraryW Loads the specified module into the address space of the calling process.
KERNEL32.DLL CreateToolhelp32Snapshot Creates a snapshot of the specified processes, heaps, threads, and modules.
KERNEL32.DLL WriteProcessMemory Writes data to an area of memory in a specified process.
KERNEL32.DLL ReadProcessMemory Reads data from an area of memory in a specified process.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
USER32.DLL GetAsyncKeyState Retrieves the status of a virtual key asynchronously.
SHELL32.DLL ShellExecuteW Performs a run operation on a specific file.
SHELL32.DLL ShellExecuteExW Performs a run operation on a specific file.
Windows REG (UNICODE)
Software\AutoIt v3\AutoIt
SOFTWARE\Classes\
SYSTEM\CurrentControlSet\Control\Nls\Language

File Access
OLEAUT32.dll
ole32.dll
SHELL32.dll
ADVAPI32.dll
COMDLG32.dll
GDI32.dll
USER32.dll
KERNEL32.dll
UxTheme.dll
USERENV.dll
IPHLPAPI.DLL
PSAPI.DLL
WININET.dll
MPR.dll
COMCTL32.dll
WINMM.dll
VERSION.dll
WSOCK32.dll
@.dat
Temp
UserProfile

File Access (UNICODE)
Macro.exe
USER32.DLL
combase.dll
xIKy0BHBbad allocationmscoree.dll
Temp
ProgramFiles
AppData
UserProfile

Interest's Words
exec
attrib
start
shutdown
systeminfo
ping
replace

Interest's Words (UNICODE)
exec
attrib
start
pause
comspec
shutdown
ping
expand
replace

IP Addresses
255.255.255.255

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii Registry (RegCreateKeyEx)
Text Ascii Registry (RegOpenKeyEx)
Text Ascii Registry (RegSetValueEx)
Text Ascii Registry (RegDeleteKeyEx)
Text Ascii File (GetTempPath)
Text Ascii File (CopyFile)
Text Ascii File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Anti-Analysis VM (GetSystemInfo)
Text Ascii Anti-Analysis VM (GlobalMemoryStatusEx)
Text Ascii Anti-Analysis VM (GetVersion)
Text Ascii Anti-Analysis VM (CreateToolhelp32Snapshot)
Text Ascii Reconnaissance (FindFirstFileW)
Text Ascii Reconnaissance (FindNextFileW)
Text Ascii Reconnaissance (FindClose)
Text Ascii Stealth (ExitThread)
Text Ascii Stealth (CloseHandle)
Text Ascii Stealth (VirtualAlloc)
Text Ascii Stealth (ReadProcessMemory)
Text Ascii Execution (CreateProcessA)
Text Ascii Execution (CreateProcessW)
Text Ascii Execution (ShellExecute)
Text Ascii Execution (ResumeThread)
Text Ascii Execution (CreateEventW)
Text Unicode Privileges (SeAssignPrimaryTokenPrivilege)
Text Unicode Privileges (SeBackupPrivilege)
Text Unicode Privileges (SeDebugPrivilege)
Text Unicode Privileges (SeIncreaseQuotaPrivilege)
Text Unicode Privileges (SeRestorePrivilege)
Text Unicode Privileges (SeShutdownPrivilege)
Text Unicode Keyboard Key (ALTDOWN)
Text Unicode Keyboard Key (ALTUP)
Text Unicode Keyboard Key (SHIFTDOWN)
Text Unicode Keyboard Key (SHIFTUP)
Text Unicode Keyboard Key (CTRLDOWN)
Text Unicode Keyboard Key (CTRLUP)
Text Unicode Keyboard Key (LWINDOWN)
Text Unicode Keyboard Key (LWINUP)
Text Unicode Keyboard Key (RWINDOWN)
Text Unicode Keyboard Key (RWINUP)
Text Unicode Keyboard Key (LBUTTON)
Text Unicode Keyboard Key (MBUTTON)
Text Unicode Keyboard Key (RBUTTON)
Text Unicode Keyboard Key (NUMPAD0)
Text Unicode Keyboard Key (NUMPAD1)
Text Unicode Keyboard Key (NUMPAD2)
Text Unicode Keyboard Key (NUMPAD3)
Text Unicode Keyboard Key (NUMPAD4)
Text Unicode Keyboard Key (NUMPAD5)
Text Unicode Keyboard Key (NUMPAD6)
Text Unicode Keyboard Key (NUMPAD7)
Text Unicode Keyboard Key (NUMPAD8)
Text Unicode Keyboard Key (NUMPAD9)
Text Unicode Keyboard Key (CapsLock)
Text Ascii Malicious rerouting of traffic to an attacker-controlled site (Redirect)
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern Microsoft Visual C++ 8
Entry Point Hex Pattern VC8 - Microsoft Corporation
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\2057 C64A4 128 C12A4 2800000010000000200000000100040000000000C000000000000000000000000000000000000000000000007A60EB00795F(....... ...................................z..y_
\ICON\2\2057 C65CC 128 C13CC 28000000100000002000000001000400000000008000000000000000000000001000000010000000000000007A60EB00795F(....... ...................................z..y_
\ICON\3\2057 C66F4 128 C14F4 2800000010000000200000000100040000000000C000000000000000000000000000000000000000000000007A60EB00795F(....... ...................................z..y_
\ICON\4\2057 C681C 15B1 C161C 89504E470D0A1A0A0000000D49484452000001000000010008060000005C72A866000000016F724E5401CFA2779A0000156B.PNG........IHDR.............\r.f....orNT...w....k
\MENU\166\2057 C7DD0 50 C2BD0 00000000900043006F006E007400650078007400310000000000A7005300630072006900700074002000260050006100750073006500640000000000000000008000A800450026007800690074000000......C.o.n.t.e.x.t.1.......S.c.r.i.p.t. .&.P.a.u.s.e.d.............E.&.x.i.t...
\DIALOG\1000\2057 C7E20 FC C2C20 0100FFFF00000000000004004C0ACC80040000000000A2005F00000000004100750074006F0049007400200049006E007000............L..........._.....A.u.t.o.I.t. .I.n.p.
\STRING\7\2057 C7F1C 594 C2D1C 0000000000000000000009002800500061007500730065006400290020000C004100750074006F0049007400200045007200............(.P.a.u.s.e.d.). ...A.u.t.o.I.t. .E.r.
\STRING\8\2057 C84B0 68A C32B0 300049006E0063006F007200720065006300740020006E0075006D0062006500720020006F006600200070006100720061000.I.n.c.o.r.r.e.c.t. .n.u.m.b.e.r. .o.f. .p.a.r.a.
\STRING\9\2057 C8B3C 490 C393C 30004500780070006500630074006500640020006100200022003D00220020006F00700065007200610074006F00720020000.E.x.p.e.c.t.e.d. .a. .".=.". .o.p.e.r.a.t.o.r. .
\STRING\10\2057 C8FCC 5FC C3DCC 1A0049006E00760061006C00690064002000660069006C0065002000660069006C0074006500720020006700690076006500..I.n.v.a.l.i.d. .f.i.l.e. .f.i.l.t.e.r. .g.i.v.e.
\STRING\11\2057 C95C8 65C C43C8 3E002200530065006C0065006300740022002000730074006100740065006D0065006E00740020006900730020006D006900>.".S.e.l.e.c.t.". .s.t.a.t.e.m.e.n.t. .i.s. .m.i.
\STRING\12\2057 C9C24 466 C4A24 4800430061006E0020007000610073007300200063006F006E007300740061006E0074007300200062007900200072006500H.C.a.n. .p.a.s.s. .c.o.n.s.t.a.n.t.s. .b.y. .r.e.
\STRING\313\2057 CA08C 158 C4E8C 00000000000000000000000000000000150055006E00610062006C006500200074006F002000700061007200730065002000..................U.n.a.b.l.e. .t.o. .p.a.r.s.e. .
\RCDATA\CWAUTCOMP\0 CA1E4 25A7B C4FE4 4357417574436F6D70A9636F64655F7761725F353039D24DA8FF7324A73CF67A12F167ACC193E72D5B6115D4138D72E1BB3ACWAutComp.code_war_509.M..s$.<.z..g....-[a....r..:
\GROUP_ICON\99\2057 EFC60 14 EAA60 0000010001000000000001002000B11500000400............ .......
\GROUP_ICON\162\2057 EFC74 14 EAA74 0000010001001010100001000400280100000200..............(.....
\GROUP_ICON\164\2057 EFC88 14 EAA88 0000010001001010100001000400280100000100..............(.....
\GROUP_ICON\169\2057 EFC9C 14 EAA9C 0000010001001010100001000400280100000300..............(.....
\VERSION\1\2057 EFCB0 284 EAAB0 840234000000560053005F00560045005200530049004F004E005F0049004E0046004F0000000000BD04EFFE000001000100..4...V.S._.V.E.R.S.I.O.N._.I.N.F.O...............
\24\1\2057 EFF34 3B9 EAD34 3C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
Intelligent String
• Macro.exe
• mscoree.dll
• combase.dll
• !"$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]_abcdefghijklmnopqrstuvwxyz{|}~kernel32.dll
• USER32.DLL
• RUNAS
• RUNASWAIT
• COMSPEC
• runas
• kernel32.dll
• oleaut32.dll
• 0.0.0.0
• .lnk
• 255.255.255.255
• .icl
• .exe
• .dll
• COMCTL32.dll
• KERNEL32.dll
• USER32.dll
• COMDLG32.dll
• 0.1.0.0
• 1.1.0.0

Flow Anomalies
Offset FlowVA Section Description
768 48F19C .text CALL [static] | Indirect call to absolute memory address
78C 48F19C .text CALL [static] | Indirect call to absolute memory address
98E 48F72C .text CALL [static] | Indirect call to absolute memory address
A6C 48F304 .text CALL [static] | Indirect call to absolute memory address
AB3 48F190 .text CALL [static] | Indirect call to absolute memory address
F4D 48F188 .text CALL [static] | Indirect call to absolute memory address
13FE 48F020 .text CALL [static] | Indirect call to absolute memory address
141F 48F028 .text CALL [static] | Indirect call to absolute memory address
1441 48F024 .text CALL [static] | Indirect call to absolute memory address
14D8 48F180 .text CALL [static] | Indirect call to absolute memory address
1598 48F344 .text CALL [static] | Indirect call to absolute memory address
1615 48F184 .text CALL [static] | Indirect call to absolute memory address
1621 48F184 .text CALL [static] | Indirect call to absolute memory address
1661 48F18C .text CALL [static] | Indirect call to absolute memory address
1673 48F190 .text CALL [static] | Indirect call to absolute memory address
16B6 48F18C .text CALL [static] | Indirect call to absolute memory address
16C8 48F190 .text CALL [static] | Indirect call to absolute memory address
17CF 48F198 .text CALL [static] | Indirect call to absolute memory address
1819 48F314 .text CALL [static] | Indirect call to absolute memory address
18F9 48F1F8 .text CALL [static] | Indirect call to absolute memory address
1928 48F838 .text CALL [static] | Indirect call to absolute memory address
193F 48F268 .text CALL [static] | Indirect call to absolute memory address
1A22 48F264 .text CALL [static] | Indirect call to absolute memory address
1A8F 48F188 .text CALL [static] | Indirect call to absolute memory address
1ACD 48F188 .text CALL [static] | Indirect call to absolute memory address
1B10 48F18C .text CALL [static] | Indirect call to absolute memory address
1B22 48F190 .text CALL [static] | Indirect call to absolute memory address
1B60 48F188 .text CALL [static] | Indirect call to absolute memory address
1BA0 48F18C .text CALL [static] | Indirect call to absolute memory address
1BB2 48F190 .text CALL [static] | Indirect call to absolute memory address
1FBE 48F1C8 .text CALL [static] | Indirect call to absolute memory address
1FF3 48F1C8 .text CALL [static] | Indirect call to absolute memory address
20D9 48F1C4 .text CALL [static] | Indirect call to absolute memory address
21AD 48F30C .text CALL [static] | Indirect call to absolute memory address
2FD3 48F61C .text CALL [static] | Indirect call to absolute memory address
3014 48F67C .text CALL [static] | Indirect call to absolute memory address
303C 48F654 .text CALL [static] | Indirect call to absolute memory address
3169 48F61C .text CALL [static] | Indirect call to absolute memory address
3182 48F67C .text CALL [static] | Indirect call to absolute memory address
3352 48F708 .text CALL [static] | Indirect call to absolute memory address
3366 48F11C .text CALL [static] | Indirect call to absolute memory address
3370 48F670 .text CALL [static] | Indirect call to absolute memory address
3526 48F4F0 .text CALL [static] | Indirect call to absolute memory address
394A 48F72C .text CALL [static] | Indirect call to absolute memory address
451D 48F660 .text CALL [static] | Indirect call to absolute memory address
679A 48F7A0 .text CALL [static] | Indirect call to absolute memory address
68C6 48F6D4 .text CALL [static] | Indirect call to absolute memory address
68D1 48F6D0 .text CALL [static] | Indirect call to absolute memory address
6917 48F6CC .text CALL [static] | Indirect call to absolute memory address
6923 48F624 .text CALL [static] | Indirect call to absolute memory address
6950 48F7A0 .text CALL [static] | Indirect call to absolute memory address
C208 48F660 .text CALL [static] | Indirect call to absolute memory address
C47E 48F660 .text CALL [static] | Indirect call to absolute memory address
DE5F 48F660 .text CALL [static] | Indirect call to absolute memory address
E81F 48F244 .text CALL [static] | Indirect call to absolute memory address
E987 48F318 .text CALL [static] | Indirect call to absolute memory address
EBAF 48F178 .text CALL [static] | Indirect call to absolute memory address
EBEA 48F178 .text CALL [static] | Indirect call to absolute memory address
ECC1 48F1CC .text CALL [static] | Indirect call to absolute memory address
EFB4 48F318 .text CALL [static] | Indirect call to absolute memory address
FF17 1800000 .text JMP [static] | Indirect jump to absolute memory address
119A3 48F1CC .text CALL [static] | Indirect call to absolute memory address
11A0E 48F178 .text CALL [static] | Indirect call to absolute memory address
11A3E 48F178 .text CALL [static] | Indirect call to absolute memory address
11C67 48F1CC .text CALL [static] | Indirect call to absolute memory address
11FA3 4BE15C .text CALL [static] | Indirect call to absolute memory address
13ADE 138840F .text JMP [static] | Indirect jump to absolute memory address
14BA3 48F4A4 .text CALL [static] | Indirect call to absolute memory address
14E56 48F7A8 .text CALL [static] | Indirect call to absolute memory address
14EFB 48F840 .text CALL [static] | Indirect call to absolute memory address
15023 48F5CC .text CALL [static] | Indirect call to absolute memory address
152B5 48F020 .text CALL [static] | Indirect call to absolute memory address
15378 48F6E4 .text CALL [static] | Indirect call to absolute memory address
153A2 48F6F4 .text CALL [static] | Indirect call to absolute memory address
153C5 48F700 .text CALL [static] | Indirect call to absolute memory address
153D0 48F6FC .text CALL [static] | Indirect call to absolute memory address
153E4 48F6F8 .text CALL [static] | Indirect call to absolute memory address
153F3 48F6F0 .text CALL [static] | Indirect call to absolute memory address
15470 48F74C .text CALL [static] | Indirect call to absolute memory address
154B0 48F728 .text CALL [static] | Indirect call to absolute memory address
1551D 48F320 .text CALL [static] | Indirect call to absolute memory address
1552F 48F31C .text CALL [static] | Indirect call to absolute memory address
155A0 48F314 .text CALL [static] | Indirect call to absolute memory address
15620 48F318 .text CALL [static] | Indirect call to absolute memory address
15767 48F4A4 .text CALL [static] | Indirect call to absolute memory address
1583E 48F4A4 .text CALL [static] | Indirect call to absolute memory address
159CE 48F0C8 .text CALL [static] | Indirect call to absolute memory address
159FD 48F624 .text CALL [static] | Indirect call to absolute memory address
15B6C 48F718 .text CALL [static] | Indirect call to absolute memory address
15B7B 48F714 .text CALL [static] | Indirect call to absolute memory address
15C23 48F70C .text CALL [static] | Indirect call to absolute memory address
15C6A 48F578 .text CALL [static] | Indirect call to absolute memory address
15D0F 48F314 .text CALL [static] | Indirect call to absolute memory address
15D5E 48F718 .text CALL [static] | Indirect call to absolute memory address
15D88 48F70C .text CALL [static] | Indirect call to absolute memory address
15D99 48F6FC .text CALL [static] | Indirect call to absolute memory address
15DB6 48F0AC .text CALL [static] | Indirect call to absolute memory address
15DC6 48F0A8 .text CALL [static] | Indirect call to absolute memory address
15DDC 48F710 .text CALL [static] | Indirect call to absolute memory address
15DEB 48F0B0 .text CALL [static] | Indirect call to absolute memory address
F5800 N/A *Overlay* 0000000000000000000000000000000000000000 | ....................
Extra Analysis
Metric Value Percentage
Ascii Code 586741 58,333%
Null Byte Code 163888 16,2935%
© 2026 All rights reserved.